nanog mailing list archives

Re: Attacking on Source Port 0 (ZERO)


From: "Dobbins, Roland" <rdobbins () arbor net>
Date: Mon, 15 Oct 2012 02:04:12 +0000


On Oct 15, 2012, at 3:57 AM, Nick Hilliard wrote:

If you haven't already configured CoPP on your BRASs, you might want to look at deploying it.

CoPP is pretty much a wash on software-based boxes; it only really helps on hardware-based boxes.  And iACLs is 
easier/a bigger win, anyways (though anyone using software-based boxes on the Internet in 2012 is just waiting to be 
zorched).

-----------------------------------------------------------------------
Roland Dobbins <rdobbins () arbor net> // <http://www.arbornetworks.com>

          Luck is the residue of opportunity and design.

                       -- John Milton



Current thread: